manage.flexfs
manage.flexfs provides optional host-level management of flexFS systemd services and the binaries in /sbin. Most subcommands require root privileges; init creds, deinit creds, deploy, license, and version do not. FlexFS servers and mount clients do not need manage.flexfs or root to run.
Persistent Flags
Section titled “Persistent Flags”These flags apply to every subcommand.
| Flag | Type | Default | Description | Visibility |
|---|---|---|---|---|
--reportErrors | bool | false | Report errors and panics to Paradigm4 | Public |
Subcommands
Section titled “Subcommands”| Subcommand | Description | Visibility |
|---|---|---|
clean | Remove downloaded flexFS binaries from /tmp | Public |
deinit creds | Remove credentials file | Public |
deploy | Deploy mount.flexfs binary to staging/production channels | Public |
download [binary...] | Download flexFS binaries to /tmp | Public |
init creds | Initialize credentials (custom download server address) | Public |
install [binary...] | Install flexFS binaries from /tmp to /sbin | Public |
license | Print license information | Public |
restart [service...] | Restart services (stop, start) | Public |
start [service...] | Start flexFS systemd services | Public |
status [service...] | Show status of flexFS services | Public |
stop [service...] | Stop flexFS systemd services (reverse order) | Public |
upgrade [binary...] | Full upgrade cycle (clean, download, install, restart affected services) | Public |
version | Print the build version | Public |
watch <service> | Follow journal logs for a flexFS service | Public |
Services
Section titled “Services”When a service argument is omitted, all services are targeted. The available service names are:
| Service | Binary | Start Order |
|---|---|---|
error | error.flexfs | 1 |
stat | stat.flexfs | 2 |
aws | aws.flexfs | 3 |
admin | admin.flexfs | 4 |
free | free.flexfs | 5 |
proxy | proxy.flexfs | 6 |
meta | meta.flexfs | 7 |
Services are started in the order shown above and stopped in reverse order. Services whose systemd unit is not installed are skipped.
Versions
Section titled “Versions”The download, install, deploy, and upgrade subcommands take a --version that is either an exact release (e.g. v1.9.1) or a version line (e.g. v1.9.x), which resolves to the newest release on that line. When --version is omitted, the version line of the running manage.flexfs build is used. A build that carries no version (a development build) stops with build version is unversioned; please specify --version.
Journal vacuuming
Section titled “Journal vacuuming”The --vacuum flag rotates the systemd journal and then deletes every archived journal file (journalctl --rotate followed by journalctl --vacuum-time=1s). This removes the past logs of every service on the host, not only flexFS services.
init creds
Section titled “init creds”manage.flexfs init creds --downloadAddr <download-addr> [--credsFile <path>] [--force]Initializes a credentials file for manage.flexfs with a custom download server address. Commands that download binaries (download, deploy, upgrade, install) read this file to resolve the server address, by default from the home folder of the user running them. download, install, and upgrade run as root and read root’s file (/root/.flexfs/manage/creds), so run init creds with sudo for them. deploy run as another user reads that user’s file. init on its own does the same thing as init creds.
| Flag | Type | Default | Description | Visibility |
|---|---|---|---|---|
--credsFile | string | ~/.flexfs/manage/creds | Credentials file path to write | Public |
--downloadAddr | string | "" | Download server address (required) | Public |
--force | bool | false | Overwrite existing credentials file | Public |
deinit creds
Section titled “deinit creds”manage.flexfs deinit creds [--credsFile <path>]Removes the credentials file. After removal, download commands fall back to the default server (get.flexfs.io).
| Flag | Type | Default | Description | Visibility |
|---|---|---|---|---|
--credsFile | string | ~/.flexfs/manage/creds | Credentials file path | Public |
sudo manage.flexfs start [--vacuum] [service...]Starts the specified flexFS systemd services. If no services are named, all installed services are started.
| Flag | Type | Default | Description | Visibility |
|---|---|---|---|---|
--vacuum | bool | false | Also vacuum system journal logs (see Journal vacuuming) | Public |
sudo manage.flexfs stop [--vacuum] [service...]Stops the specified services in reverse order to respect dependencies.
| Flag | Type | Default | Description | Visibility |
|---|---|---|---|---|
--vacuum | bool | false | Also vacuum system journal logs (see Journal vacuuming) | Public |
restart
Section titled “restart”sudo manage.flexfs restart [--vacuum] [service...]Stops and starts the specified services.
| Flag | Type | Default | Description | Visibility |
|---|---|---|---|---|
--vacuum | bool | false | Also vacuum system journal logs (see Journal vacuuming) | Public |
status
Section titled “status”sudo manage.flexfs status [service...]Shows the active state and uptime of each installed service.
sudo manage.flexfs clean [--vacuum]Removes flexFS temporary files (/tmp/*.flexfs). Optionally vacuums systemd journal logs.
| Flag | Type | Default | Description | Visibility |
|---|---|---|---|---|
--vacuum | bool | false | Also vacuum system journal logs (see Journal vacuuming) | Public |
download
Section titled “download”sudo manage.flexfs download [--version <ver>] [--arch <arch>] [--install] [binary...]Downloads the specified flexFS binaries to /tmp, after first removing any /tmp/*.flexfs files. With no binary names, it downloads the binaries already installed in /sbin. Uses the download server address from the credentials file, or get.flexfs.io by default.
| Flag | Type | Default | Description | Visibility |
|---|---|---|---|---|
--arch | string | host architecture | Architecture to download (e.g. amd64, aarch64) | Public |
--credsFile | string | ~/.flexfs/manage/creds | Credentials file path | Public |
--downloadAddr | string | "" | Download server address (overrides credentials file) | Internal |
--install | bool | false | Install binaries to /sbin after downloading | Public |
--version | string | build’s version line | Version or version branch to download (e.g. v1.9.1, v1.9.x) | Public |
install
Section titled “install”sudo manage.flexfs install [--version <ver>] [--arch <arch>] [binary...]Installs flexFS binaries from /tmp to /sbin. A file in /tmp is installed only if it is a regular, single-link file owned by root and not writable by group or others. When binary names are given, only those are installed, and any that are missing from /tmp or do not qualify are downloaded first. Without names, every qualifying flexFS binary in /tmp is installed and files that do not qualify are skipped. Each binary replaces the installed one in a single step, and its SELinux label is restored from policy with restorecon when available, or set to bin_t with chcon otherwise. install also removes /sbin/update.flexfs if present.
| Flag | Type | Default | Description | Visibility |
|---|---|---|---|---|
--arch | string | host architecture | Architecture to download for missing binaries | Public |
--credsFile | string | ~/.flexfs/manage/creds | Credentials file path (used when downloading missing binaries) | Public |
--downloadAddr | string | "" | Download server address (overrides credentials file) | Internal |
--version | string | build’s version line | Version or version branch for missing binaries (e.g. v1.9.1, v1.9.x) | Public |
deploy
Section titled “deploy”manage.flexfs deploy [--channel <channel>] [--version <ver>] [--adminPath <path>]Downloads mount.flexfs for both architectures and places them in the deploy folder under --adminPath, from which the admin server serves mount client installs and auto-updates.
deploy does not require root. Run it as the user that runs the admin server, or as any user that can write to --adminPath. When run as root, it gives the deploy folder, its channel folders, and each version it deploys the owner and group of --adminPath, so an admin server that runs as another user can read them.
deploy does nothing on a host without an admin server, such as a Community installation. If --adminPath contains neither the admin database (db) nor the admin credentials file (creds), it prints No admin server found in <path>; nothing to deploy and exits successfully without downloading anything. When --adminPath is given explicitly and holds neither file, deploy exits with an error instead.
| Flag | Type | Default | Description | Visibility |
|---|---|---|---|---|
--adminPath | string | ~/.flexfs/admin | Admin folder path, in the home folder of the user running the command | Public |
--channel | string | all | Deployment channel: staging, production, or all | Public |
--credsFile | string | ~/.flexfs/manage/creds | Credentials file path | Public |
--downloadAddr | string | "" | Download server address (overrides credentials file) | Internal |
--version | string | build’s version line | Version or version branch to deploy (e.g. v1.9.1, v1.9.x) | Public |
upgrade
Section titled “upgrade”sudo manage.flexfs upgrade [--version <ver>] [--arch <arch>] [--vacuum] [--deploy [--channel <channel>] [--adminPath <path>]] [binary...]Performs a full upgrade: cleans state, downloads and installs binaries, then restarts only the services whose binaries were upgraded (not all services). When no binary names are given, it upgrades every flexFS binary found in /sbin. With --deploy, it then deploys mount.flexfs for the upgraded version — equivalent to running deploy afterward, reusing the same --version. On a host without an admin server, the deploy step does nothing and the upgrade still succeeds.
| Flag | Type | Default | Description | Visibility |
|---|---|---|---|---|
--adminPath | string | ~/.flexfs/admin | Admin folder path (used with --deploy) | Public |
--arch | string | host architecture | Architecture to download | Public |
--channel | string | all | Deployment channel for --deploy: staging, production, or all | Public |
--credsFile | string | ~/.flexfs/manage/creds | Credentials file path | Public |
--deploy | bool | false | After upgrading, also deploy mount.flexfs (equivalent to running deploy) | Public |
--downloadAddr | string | "" | Download server address (overrides credentials file) | Internal |
--vacuum | bool | false | Also vacuum system journal logs (see Journal vacuuming) | Public |
--version | string | build’s version line | Version or version branch to download (and deploy with --deploy) | Public |
sudo manage.flexfs watch [--lines <n>] [--cat] <service>Follows journal logs for a flexFS service using journalctl -f.
| Flag | Type | Default | Description | Visibility |
|---|---|---|---|---|
--cat | bool | false | Use plain text output (journalctl -o cat) | Public |
--lines | int | 100 | Number of recent log lines to show | Public |